CodeRed Detection and Removal Tool icon

CodeRed Detection and Removal Tool

4.7/5 9
Certified 100% CLEAN Freeware   

A simple and effective way of erasing the CodeRed malware #CodeRed antivirus  #CodeRed remover  #Worm cleaner  #CodeRed  #Antivirus  #Remover  

Description

Free Download

CodeRed Detection and Removal Tool is a lightweight utility that targets the Win32.IISWorm.CodeRed.F worm.

The virus exploits a buffer overflow vulnerability in the Microsoft Windows IIS Server, that runs on Microsoft Windows NT and Windows 2000. The patch and information about this problem can be found at the address:

http://www.microsoft.com/technet/security/bulletin/MS01-033.asp

The worm begins spreading itself by sending HTTP queries. Unpatched machines will execute the worm code directly from memory. Once executed, the worm scans kernel32.dll 's export table for the GetProcAddress function and then finds the addresses of the functions needed for further spreading. It then exploits yet another bug in Microsoft Windows, the relative shell path vulnerability.

This particular vulnerability is used to load another shell program instead of the usual explorer.exe (found in %WINDIR%) by writing a file named explorer.exe in the %SYSTEMROOT% directory. The worm checks whether Chinese (either Traditional or Simplified) is the language installed on the system. If it is Chinese, it creates 600 threads and spreads for 48hours. On a non-Chinese system it creates 300 threads and spreads for 24 hours.

After that, it reboots the system using ExitWindowEx function. The worm dumps part of its body to %SYSTEMROOT%explorer.exe, which is in fact a trojan component, allowing the attacker to remotely access the infected computers.

The trojan component modifies the registry key:

[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\SFCDisable]

to disable file system security and allows a remote attacker to access drives C: and D: via a web browser by adding read/write rights using the registry key:

[HKLM\SYSTEM\CurrentControlSet\Services\W3SVC\Parameters\Virtual Roots]

CodeRed Detection and Removal Tool 1.0.0.115

add to watchlist add to download basket send us an update REPORT
  runs on:
Windows NT
Windows 7
Windows Vista
Windows 2K
  file size:
31 KB
  filename:
codered.zip
  1 screenshot:
CodeRed Detection and Removal Tool - CodeRed Detection and Removal Tool quickly scans and cleans the virus from any infected system.
  main category:
Antivirus
  developer:
  visit homepage

Windows Sandbox Launcher

Set up the Windows Sandbox parameters to your specific requirements, with this dedicated launcher that features advanced parametrization
Windows Sandbox Launcher

Bitdefender Antivirus Free

Feather-light and free antivirus solution from renowned developer that keeps the PC protected at all times from malware without requiring user configuration
Bitdefender Antivirus Free

IrfanView

With support for a long list of plugins, this minimalistic utility helps you view images, as well as edit and convert them using a built-in batch mode
IrfanView

ShareX

Capture your screen, create GIFs, and record videos through this versatile solution that includes various other amenities: an OCR scanner, image uploader, URL shortener, and much more
ShareX

Microsoft Teams

Effortlessly chat, collaborate on projects, and transfer files within a business-like environment by employing this Microsoft-vetted application
Microsoft Teams

4k Video Downloader

Export your favorite YouTube videos and playlists with this intuitive, lightweight program, built to facilitate downloading clips from the popular website
4k Video Downloader

calibre

Effortlessly keep your e-book library thoroughly organized with the help of the numerous features offered by this efficient and capable manager
calibre

Context Menu Manager

Customize Windows’ original right-click context menu using this free, portable and open-source utility meant to enhance your workflow
Context Menu Manager

Zoom Client

The official desktop client for Zoom, the popular video conferencing and collaboration tool used by millions of people worldwide
Zoom Client

7-Zip

An intuitive application with a very good compression ratio that can help you not only create and extract archives, but also test them for errors
7-Zip

% discount
Context Menu Manager
  • Context Menu Manager
  • Zoom Client
  • 7-Zip
  • Windows Sandbox Launcher
  • Bitdefender Antivirus Free
  • IrfanView
  • ShareX
  • Microsoft Teams
  • 4k Video Downloader
  • calibre
essentials


Click to load comments
This enables Disqus, Inc. to process some of your data. Disqus privacy policy